Skip to content

Guide

GDPR compliance checklist for technology companies outside Europe

Reviewed 2026-08-07

Short answer

The GDPR can reach a company with no EU office when it offers goods or services to people in the EU or monitors their behaviour there. It can also arrive through a contract when a European customer gives the company personal data to process. A useful checklist must keep those direct and customer-driven routes separate rather than treating a country, certification or contract template as the answer.

See the full 10-step checklist below.

Why this matters

Who should care
Companies processing personal data in EU-related contexts.
Typical trigger
Direct GDPR territorial-scope conditions, or an EU customer's own processing requirements.
What buyers may ask for
DPAsubprocessor informationsecurity measurestransfer safeguards

Where this fits

  1. 01

    Your company

    Processes personal data reachable by EU data-protection law, directly or on behalf of an EU customer.

  2. 02

    EU customer

    May be a controller that pushes GDPR obligations down to you through a Data Processing Agreement.

  3. 03

    Person in the EU

    Whose data is involved: this is what determines whether GDPR's territorial scope applies at all.

Who this is relevant to

This guide is for SaaS, platforms, marketplaces and technology services operating outside Europe while serving EU people or processing personal data for EU customers.

It is also useful for teams that have just received a data processing agreement, transfer assessment or privacy questionnaire from a European buyer.

  • Products used by people located in the EU
  • Vendors processing customer records or support data for a European business
  • Teams mapping cloud, engineering and subprocessor access to EU-origin data
  • Companies preparing security, privacy and transfer evidence for a European deal

Two ways the GDPR can reach a company outside Europe

The GDPR can apply directly when a company offers goods or services to people located in the EU or monitors their behaviour there. An EU office is not required for either route.

A separate customer-driven route exists when an EU customer gives the company personal data to process on its behalf. The resulting processor relationship is contractual, but the customer is required to put prescribed terms and controls in place.

Accessibility alone is not the same as targeting, and a country of incorporation does not decide applicability. The facts about people, activities, roles and data flows matter.

Direct application vs customer flow-down

A direct obligation can be pursued by a supervisory authority independently of one customer relationship. A customer-driven obligation is experienced through the contract and the evidence the customer needs to manage its own obligations. One company can have both roles for different data sets.

  • Direct: the company determines purposes or targets people in the EU in a relevant way
  • Customer-driven: the company processes data on documented instructions from a European customer
  • Both: marketing, product and customer data can create different roles at the same time

What European customers typically ask you to produce

European buyers rarely ask “are you GDPR compliant?”. They ask for artefacts, and the deal moves at the speed you can produce them.

  • A signed data processing agreement on their paper, or a credible one on yours
  • A current subprocessor list, with a mechanism for notifying changes
  • Where personal data is stored and which countries your staff access it from
  • Your technical and organisational security measures, in writing
  • A breach notification commitment with a defined timeframe
  • A named privacy contact who can answer questions without escalation
  • Your position on international transfers, and any assessment behind it
  • Evidence that data subject requests reaching your customer can be actioned in your system

Common misconceptions

“We have no EU entity, so the GDPR cannot apply to us.”
Establishment is one route into scope, not the only one. Targeting people in the EU or monitoring their behaviour brings a non-EU company into scope directly.
“We are PDPA compliant, so we are essentially there.”
The PDPA gives you a real head start: an inventory, a named owner, breach processes. But the scope, the individual rights, the lawful basis analysis and the documentation a European buyer expects all differ. Treat the PDPA as foundation, not equivalence.
“We are B2B, so we do not process personal data.”
Business contact details, user accounts, support tickets, session recordings and product analytics are all personal data when they relate to identifiable people.
“Our cloud provider is certified, so transfers are covered.”
Your provider's certifications concern their own operations. The transfer position for data you receive is yours to establish, and your customer will ask you for it.
“Signing Standard Contractual Clauses closes the transfer question.”
Clauses are one possible mechanism, and using them generally requires an assessment of the destination. Do not promise a mechanism in a questionnaire before you have established it is the right one.

Practical checklist

  1. 01Establish whether you are a controller, a processor, or both, separately for each dataset you hold
  2. 02Write down which of your activities involve people located in the EU, and why
  3. 03Map where EU personal data is stored and from which countries it is accessed, including by your own engineers
  4. 04Prepare a data processing agreement you can offer, rather than only reacting to your customer's
  5. 05Maintain a subprocessor register you can send without editing it first
  6. 06Document your security measures at a level of detail a buyer's security team will accept
  7. 07Define your breach detection and notification path, with a timeframe you can actually meet
  8. 08Name a privacy owner internally, even if the role is part-time
  9. 09Establish your transfer position before a buyer asks. Do not improvise it in a questionnaire
  10. 10Check whether your website and product use cookies or device storage that require consent

Evidence to assemble before a European deal

Work dataset by dataset: identify the role, the people involved, where data is stored and accessed, the subprocessors involved, and the security and breach processes that support the service.

Treat international transfers as an assessment question rather than assuming that a familiar contract or provider certification settles it. Keep the reasoning and supporting evidence with the relevant data flow.

The checklist is a readiness aid. It does not certify compliance or determine whether the GDPR applies to a particular company.

Cookies and device storage are a separate rulebook

Consent for cookies, SDKs and similar device storage comes from the ePrivacy Directive, implemented in national law, not from the GDPR itself. A Singapore company can be broadly in order on data protection and still be non-compliant on the consent banner in its EU-facing product.

Official EU sources

Every conclusion on this page traces back to the primary legal text. We link only to official EU sources.

RegulationsMethodologySee what the EU Readiness Pack includes

Mini-check: does this reach you?

Three questions. Your answers carry into the full assessment, so nothing is asked twice.

Do individuals located in the EU use your product or receive your services?

Employees of a European customer count.

Do you hold or process personal data on behalf of a European customer?

This covers data in your systems tied to an identifiable person.

Is that data stored or accessed from outside Europe?

Include access by your own team and relevant subprocessors.

Start the full assessment instead

General information, not legal advice. Applicability can depend on facts and national implementation. Verify material legal conclusions with qualified counsel.